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SECRET 


23 AUG 1971 


MEMORANDUM FOR: Acting Chief, DDS Plans Staff 


SUBJECT : Comments on Preliminary Draft of FY 1971 
PFIAB Report 


1. The extracts of the preliminary draft of the FY 1971 
PFIAB Report forwarded on 17 August 1971 with a request for com- 
ments and/or revisions have been reviewed. 


2. The Office of Security concurs in the content of the extracts 
with the exception of the paragraph outlining computer security 
activities on the final page of Section IV (Information Processing and 
Exploitation). 


3. This paragraph, which begins "Computer security is... .', 
more appropriately belongs under its own heading Computer Security 
ae a lettered subsection of Counterintelligeace in the sequence 
enumerated as Personnel Security, Physical Security, and Communi- 
cations Security. In additiea, it should be amended and expanded to 
be more truly representative of our FY 1971 computer security 
activities. 


4. Lwould, therefore, suggest deletion of the noted paragraph 
in Section IV and inclusion of the following as an additioaal lettered 
subsection under Counterintelligence: 


x. Computer Security 


Computer security continues as an area of increasing 
Agency concern and attention. Our capabilities for addressing 
ADP security problems were greatly enhanced during FY 1971 
by the assignment of additional personnel to our computer 
security program and the acquisition of increased technical 
competence. 
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During the year the responsibilities of our Office of 
Security in this area were further refined to include: (1) 
Development of uniform computer security policy and stan- 
dards for Agency implementation; (2) Initiation of a coordi- 
nated Agency program for the identification and resolution 
of ADP Security problems; (3) Provision of continuing 
guidance to Agency computer components in handiing the 
security probleme related to modern information processing 
techniques; (4) Conduct of security audit of Agency computer 
operations, to include the security analysis, testing, and 
evaluation of our computer systems; and (5) Support of other 
government computer security efforts where the Agency is 
requested to provide assistance. 


Specific computer security efforts initiated and/or com- 
pleted in the fiscal year included the following: 


(L} Development of Agency security standards and 
procedures for the installation and operation of re- 
mote terminal devices. 


(2) A review of Agency control procedures for com- 
puter storage media, e«.g., magnetic tapes. 


(3) Recommendations for improvements in design of 
security features in the Generalized Information Manage- 
ment System (GIMS) software package. 


(4) Development of methods to inhibit user entry into 
the supervisor state of software used on some Agency 
aysteme. 


(5) Inauguration of a four-week part-time computer 
security seminar for both security officers and com- 
puter specialists. 


(6) Continuing support in the form of computer security 
guidance and inspections to computer operations at 
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Agency Headquarters and at selected contractor sites. 


(7) Continued security supsort of community ADP efforts, 
especially those of the USIB Computer Security Subcommittee. 
The Agency has aiso provided assistance to other govern- 
mental groupe or has at least monitored such other efforts 
relating to the protection of data in modern computer 
ayaterne; arnong these efforts have been the activities of 

the Computer Science and Engineering Board of the Nationai 
Academy of Sciences and the United ftates Communications 
Security Board. 
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Acting Director of “ecurity 
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